This update for samba to version 4.10.17 fixes the following issues: - Fixed net command unable to negotiate SMB2; (bsc#1174120); - Update to 4.10.17 - CVE-2020-10745: Invalid DNS or NBT queries containing dots use several seconds of CPU each; (bso#14378); (bsc#1173160). - CVE-2020-10730: NULL de-reference in AD DC LDAP server when ASQ and VLV combined; (bso#14364); (bsc#1173159). - CVE-2020-10760: Fix use-after-free in AD DC Global Catalog LDAP server with paged_result or VLV; (bso#14402); (1173161). - CVE-2020-14303: Fix endless loop from empty UDP packet sent to AD DC nbt_server; (bso#14417); (bsc#1173359). - CVE-2020-10730: NULL de-reference in AD DC LDAP server when ASQ and VLV combined, ldb: Bump version to 1.5.8; (bso#14364); (bsc#1173159).
#1141267 #1144902 #1154289 #1154598 #1158108
#1158109 #1160850 #1160852 #1160888 #1169850
#1169851 #1173159 #1173160 #1173359 #1174120
Cross- CVE-2019-10197 CVE-2019-10218 CVE-2019-14833
CVE-2019-14847 CVE-2019-14861 CVE-2019-14870
CVE-2019-14902 CVE-2019-14907 CVE-2019-19344
CVE-2020-10700 CVE-2020-10704 CVE-2020-10730
CVE-2020-10745 CVE-2020-10760 CVE-2020-14303
Affected Products:
SUSE Linux Enterprise Software Development Kit 12-SP5
SUSE Linux Enterprise Server 12-SP5
SUSE Linux Enterprise High Availability 12-SP5
https://www.suse.com/security/cve/CVE-2019-10197.html
https://www.suse.com/security/cve/CVE-2019-10218.html
https://www.suse.com/security/cve/CVE-2019-14833.html
https://www.suse.com/security/cve/CVE-2019-14847.html
Get the latest Linux and open source security news straight to your inbox.